CVE-2026-50349
massLocal Privilege Escalation via Race Condition in Windows WinSock AFD Driver
CVE-2026-50349 is a race condition (CWE-362, also associated with use-after-free, CWE-416) in the Windows Ancillary Function Driver for WinSock (AFD), a kernel driver that provides Winsock socket functionality. A local, authorized (low-privileged) attacker can trigger concurrent operations on a shared resource with improper synchronization, which can lead to exploitable memory corruption in the kernel. Successful exploitation allows the attacker to elevate privileges locally, gaining high-impact access to confidentiality, integrity, and availability on the targeted machine (CVSS 3.1 score of 7.0 High, with local attack vector, high attack complexity, and no user interaction required). Because the AFD driver ships in-box with Windows, all Windows systems running affected builds are potentially exposed; the source data does not specify which Windows versions, so consult Microsoft's advisory for the exact affected range. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation within 30 days (9th percentile).
What to do: Apply Microsoft's security update addressing CVE-2026-50349 via Windows Update on all Windows endpoints and servers, and confirm affected builds against Microsoft's advisory since version ranges are not specified here. Prioritize systems where untrusted or low-privileged users have local, terminal-server, or RDP access, as exploitation requires local execution. Given high attack complexity, no public PoC, and low EPSS, patching within your normal update cycle is reasonable, but do not defer indefinitely.
| Microsoft Windows Ancillary Function Driver for WinSock (AFD, afd.sys) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.